Doublecup ClickFix is a threat campaign tracked by ThreatCluster, appearing in 1 threat cluster built from 1 intelligence report mention.
Doublecup ClickFix is a threat campaign tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed August 3, 2026; most recent activity August 3, 2026.
The DOUBLECUP loader-as-a-service, identified by SOCRadar, employs ClickFix attacks to conceal malware within PNG images cached by browsers. This service, operational since June 2026, targets Windows and macOS systems,…
Doublecup ClickFix is a threat campaign tracked by ThreatCluster, appearing in 1 threat cluster built from 1 intelligence report mention.
The most recent intelligence report mentioning Doublecup ClickFix on ThreatCluster is dated August 3, 2026.
Across ThreatCluster reporting, Doublecup ClickFix most frequently co-occurs with Malware, Phishing, Hubspot, NetSuite, Salesforce, among 12 tracked related entities.
The most significant recent cluster is “DOUBLECUP Service Delivers Malware via Cached PNG Images” (4 articles · Updated August 4, 2026). Doublecup ClickFix appears across 1 threat cluster in total, listed above with sources.
Doublecup ClickFix appears in 1 intelligence report mention across 1 deduplicated threat cluster, aggregated from 17,000+ monitored sources.